Privacy policy

When you use SAQ, we process data about you. Here you will find what we process, why, how long we keep it, who else is involved, and what rights you have. All of it is written from how the service actually works.

Last updated: 2026-09-19

This policy explains how ArktIQ IT AS processes personal data in connection with SAQ ("SAQ"), the service at https://saq.no. It is written to match what the software does. Where SAQ processes data on behalf of a customer organization, the data processing agreement applies in addition.

1. Who is responsible?

ArktIQ IT AS, org.nr. 937 045 670, Tomasjordvegen 129, 9024 Tomasjord, Norway. Contact: , +47 47 45 56 50. ArktIQ IT has not appointed a data protection officer; the address above handles all privacy questions.

2. Which role does ArktIQ IT have for my data?

Two roles, depending on the data.

  • Controller for the data ArktIQ IT needs to run the service and its customer relationships: your login identity, your sessions, the organization that pays and its subscription, correspondence with us, and the security and operational logs of the platform. Sections 3 to 5 describe this.
  • Processor for everything inside a workspace: tickets, comments, attachments, email, contacts, clients and client users, time entries, rate cards, billing runs, timesheets, and the workspace audit log. The customer organization that owns the workspace decides what goes in and is the controller; ArktIQ IT acts on its instructions under the data processing agreement. Section 6 describes this.

If you are an employee of a SAQ customer, or a client user invited by one, questions about the content of a workspace go to that organization. We help them answer.

3. What does ArktIQ IT process as controller, and why?

DataDetailsPurpose and legal basis
Login identityName, email address, password hash, passkey public keys, two-factor secret and recovery codes, language and timezone preferences, notification setting.To let you log in and use SAQ. Contract (GDPR art. 6(1)(b)); for client users invited by a customer, our legitimate interest in providing the service the customer asked for (art. 6(1)(f)).
SessionsSession id, creation and expiry, IP address and browser identifier at login, authentication method and time, two-factor status, single sign-on connection used.To keep you logged in, let you see and revoke your sessions, and detect misuse. Contract and legitimate interest in security.
Password breach checkWhen you set a password, the first five characters of its SHA-1 hash are sent to the Pwned Passwords service (k-anonymity). The password itself never leaves SAQ.To refuse passwords known from data breaches, as NIST 800-63B recommends. Legitimate interest in security.
API keysKey name, hash, scopes, the workspace and projects it may reach, optional network restriction, expiry, last use, and the person who minted it.To let you and your tools use the API. Contract.
Organization and subscriptionOrganization name, plan, trial and subscription state, the Stripe customer and subscription identifiers, the owner's email address given to Stripe.To provide and bill the service. Contract, and legal obligation for bookkeeping records (art. 6(1)(c)).
Correspondence with usEmail you send to us about a workspace, support, sales, or security.To answer you. Legitimate interest.
Platform emailInvitations, magic links, password resets, security notices, and subscription notices sent to your address.To operate accounts. Contract.
Security and operational logsFailed login and rate-limit counters per address and identity; application logs with request path, status, timing, workspace id, actor id, and trace id; the platform audit log of operator actions; the redacted email ingest log (message ids, sender domain, recipient mailbox, size, decision, never subject, body, sender name, or attachment names).To keep the service secure and working. Legitimate interest.
Public websiteNothing. The public pages set no cookies, load no third-party resources, and run no analytics. The web server keeps ordinary access logs for a short time.Legitimate interest in serving and protecting the site.

4. Which cookies does SAQ set?

Only strictly necessary ones: the session cookie, short-lived login challenges, and your language, workspace, and theme preferences. There are no analytics or advertising cookies and no consent banner. The cookie policy lists each cookie with its lifetime.

5. Who else receives data (sub-processors and third parties)?

ProviderWhatWhere
Hetzner Online GmbHServers, object storage for attachments, documents, and exports, and backups. Everything SAQ stores.Germany and Finland (EU).
Brevo (Sendinblue SAS)Delivery of platform email: invitations, magic links, password resets, security and subscription notices. Receives the recipient address and the message. Never workspace email, ticket content, or timesheets.France (EU).
StripeSubscription payments. Receives the organization's owner email, organization id, and what you enter at checkout: name, address, VAT number, and card details. Card details never reach SAQ.Stripe Payments Europe Ltd, Ireland; Stripe may transfer data to the United States under its own safeguards.
Have I Been Pwned (Pwned Passwords)A five-character hash prefix when a password is set. No identifier accompanies it.Global service; the data sent is not personal data.
MicrosoftOnly when a customer connects a Microsoft 365 mailbox. SAQ then reads and sends mail through that customer's own Microsoft tenant. Microsoft is the customer's provider, not ours.The customer's tenant region.
Grafana observability stackApplication logs, traces, and metrics as described in section 3, shipped to a Grafana installation ArktIQ IT operates itself. No ticket content, email content, or time entry notes.Operated by ArktIQ IT.

PDF rendering (Gotenberg) and the job queue run inside SAQ's own environment and are not third parties. ArktIQ IT does not sell or share personal data for advertising. Changes to this list are announced to workspace owners in advance as the data processing agreement requires.

6. What does SAQ process on behalf of customers?

Inside a workspace, on the customer organization's instructions:

  • People: workspace users (name, email, role, consultant category, timezone), client users and contacts (name, email address, client), billing recipients.
  • Work: tickets, descriptions, comments in three audiences, attachments, links, system events, labels, dates, estimates.
  • Email: messages received in and sent from the connected mailbox, including headers and attachments, and the encrypted mailbox credentials.
  • Time and billing: time entries with date, duration, and notes, consultant categories, rate cards, billing policies, time banks and their ledgers, billing runs, and client timesheet documents.
  • Configuration: workflow, kinds, priorities, labels, verified domains, single sign-on configuration with encrypted secrets, SCIM tokens, API keys.
  • Workspace audit log: who did what, when, and why, for privileged actions.

Client users see only what the customer's visibility rules allow: their own tickets, shared comments, and billable minutes, never internal notes, rates, or other clients. Those rules are enforced by SAQ, not left to the customer's discipline.

7. How long is data kept?

DataRetention
Login identityUntil you delete it (Account → Security) or it is deleted at your request. The identity row becomes a tombstone without name or address; workspace records that referred to you are pseudonymized ("Former member").
SessionsFull-login sessions expire after 30 days of inactivity and at most 90 days; magic-link sessions after 24 hours. Magic links are valid for 15 minutes and single use.
Workspace contentWhile the workspace exists. Tickets can be archived, deleted, or redacted by the customer under the rules in the app.
Raw email copies90 days after receipt, for re-parsing and disputes. The parsed comment and attachments stay with the ticket.
Email ingest log180 days.
Audit logs, billing runs, timesheet documentsWhile the workspace exists. The customer can redact descriptive content; financial structure is kept.
Workspace export packagesThe latest package per owner is downloadable; older packages are deleted after 7 days.
Deleted workspacesRead-only and restorable for 30 days, then everything is purged.
Backups30 days, then they age out. Deletions and redactions are replayed onto any restore before data is served.
Organization and subscription recordsWhile the subscription exists, then as long as bookkeeping law requires for invoicing records.
Security and application logsShort rotation; the platform audit log of operator actions is kept as long as the platform runs.

8. Where is data stored and is it transferred outside the EEA?

SAQ runs on servers in the EU, and all storage and backups are in the EU. The exceptions are listed in section 5: Stripe may process payment data outside the EEA under its own transfer safeguards, and the password breach check sends a hash prefix that identifies no one. Where a customer connects a Microsoft 365 mailbox, mail stays in the customer's own tenant.

9. How is the data protected?

Row-level isolation between workspaces enforced in the database, two-factor login for owners and admins, passkeys, encrypted mailbox and single sign-on secrets, TLS everywhere, continuous backups, an append-only audit trail, and a release process that scans every change. The security overview describes the measures in detail.

10. What are my rights?

You may ask for access to, correction of, deletion of, or restriction of your personal data, receive it in a portable format, and object to processing based on legitimate interest. You can do much of this yourself: your profile, sessions, passkeys, and two-factor settings are under Account, and you can delete your identity from Account → Security. A workspace owner can export the whole workspace. For anything else, write to the address in section 1; we answer within one month. Requests about the content of a workspace are forwarded to the customer organization that controls it, and we help them answer. You may also complain to the Norwegian Data Protection Authority, Datatilsynet.

11. Changes

Changes are announced here with a new "last updated" date; material changes are also sent to workspace owners by email.